Thank you for reaching out.
Based on your questions above
If an organisation has ExpressRoute with Microsoft peering enabled, is ER used for all traffic for enabled service tags or only those services hosted in the same tenant?
Yes, it is enabled for the service tags. As documented here
If your ExpressRoute circuit is enabled for Azure Microsoft peering, you can access the public IP address ranges used in Azure over the circuit. Azure Microsoft peering provides access to services currently hosted on Azure (with geo-restrictions depending on your circuit's SKU). To validate availability for a specific service, you can check the documentation for that service to see if there's a reserved range published for that service. Then, look up the IP ranges of the target service and compare with the ranges listed in the Azure IP Ranges and Service Tags – Public Cloud XML file.
Example scenario: connecting to a storage account hosted in a customer's tenant rather than my organisation?
Yes, you can access the storage account hosted in a customer's tenant over Microsoft Peering. For storage account with Network restriction, to allow access to your service resources, you must allow these public IP addresses in the firewall setting for resource IPs. For Microsoft peering, either the service provider or the customer provides the NAT IP addresses. More details can be found here.
Below are some helpful FAQ's regarding this set-up.
- https://video2.skills-academy.com/en-us/azure/expressroute/expressroute-faqs#if-i-pay-for-unlimited-data-do-i-get-unlimited-egress-data-transfer-for-services-accessed-over-microsoft-peering
- https://video2.skills-academy.com/en-us/azure/expressroute/expressroute-faqs#how-is-redundancy-implemented-for-microsoft-peering
- https://video2.skills-academy.com/en-us/azure/expressroute/expressroute-faqs#how-do-i-ensure-that-my-traffic-destined-for-azure-public-services-like-azure-storage-and-azure-sql-on-microsoft-peering-or-public-peering-is-preferred-on-the-expressroute-path
Hope this helps! Please let me know if you have any additional questions. Thank you!
Please "Accept the answer" if the information helped you. This will help us and others in the community as well.